Methods and systems of isolated backup

TW202636287AActive Publication Date: 2026-09-01QNAP SYST INC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
TW114105835
Authority / Receiving Office
TW · TW
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-02-18
Publication Date
2026-09-01
Estimated Expiration
2045-02-17

AI Technical Summary

Technical Problem

Existing isolation backup methods expose target backup electronic devices to cybersecurity threats through public networks during data transfer, increasing the risk of data loss.

Method used

A method involving a network manager, a bridging electronic device, and a target backup electronic device to establish and terminate communication connections, ensuring data isolation and preventing external threats by copying data through a bridging device before disconnecting from public networks.

Benefits of technology

Ensures secure data transfer by isolating the target backup device from public networks, preventing cybersecurity threats and maintaining data integrity.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure TWG2TA001073678_001
    Figure TWG2TA001073678_001
  • Figure TWG2TA001073678_002
    Figure TWG2TA001073678_002
  • Figure TWG2TA001073678_003
    Figure TWG2TA001073678_003
Patent Text Reader

Abstract

A method for data isolation backup, the method includes: a network manager communicatively connected to a bridging electronic device; the network manager receives a first task execution instruction; the network manager communicatively connects to a source electronic device; the source electronic device transmits the first data to the bridging electronic device; the network manager receives a second task execution instruction; the network manager disconnects from the source electronic device and communicatively connects to a target backup electronic device; the bridging electronic device transmits the second data to the target backup electronic device; the network manager disconnects from the target backup electronic device.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a method and system for isolation backup, and in particular, it uses an electronic device to issue instructions to control a network manager to establish or terminate communication between the network manager and an electronic device where another backup data source is located and another electronic device where the backup data is located, so as to achieve the storage of the data to be backed up in an electronic device isolated from external networks or public networks. [Previous Technology]

[0002] A common isolation backup method is to establish an isolation barrier between an electronic device that is connected to a public network (such as the source electronic device described in the invention) and an electronic device that wants to store backup data (such as the target backup electronic device described in the invention) when the backup task is not executed. If the communication connection between the two electronic devices is interrupted, the cybersecurity threat cannot reach the target backup electronic device through the source electronic device. However, when the backup task is executed, the isolation barrier will be removed, and the two electronic devices will have a communication connection. This means that the cybersecurity threat may be able to enter the target backup electronic device through the public network, which increases the risk of loss of backup data. [Summary of the Invention]

[0003] In order to solve the data security problem mentioned in the prior art, the present invention proposes an isolation backup method to achieve the purpose of communication isolation of the target backup electronic device, and to prevent cybersecurity threats from entering the target backup electronic device through public networks or external networks and stealing important backup data.

[0004] An isolation backup method is performed by at least one source electronic device, a bridging electronic device, a target backup electronic device and a network manager, the steps of which are as follows.

[0005] First, the network manager is connected to the bridging electronics.

[0006] Next, the bridging electronic device sends a first task execution command to the network manager.

[0007] Next, the network manager communicates with the source electronic device and sends a first task execution instruction to the source electronic device.

[0008] Next, the source electronic device copies and transmits the first data to the bridging electronic device according to the first task execution instruction, and the bridging electronic device stores the first data.

[0009] Next, the bridging electronic device sends a second task execution instruction to the network manager.

[0010] Then, the network manager disconnects the communication connection with the source electronic device and the network manager communicates with the target backup electronic device.

[0011] Next, the bridging electronic device copies and transmits the second data to the target backup electronic device according to the second task execution instruction, and the target backup electronic device stores the second data.

[0012] Finally, the network manager terminates the communication connection with the target backup electronic device.

[0013] In one embodiment, after the source electronic device detects the security of a public network or an external network, the source electronic device can be communicatively connected to the public network or the external network.

[0014] In one embodiment, the bridging electronic device has a task scheduling function, through which the user of the bridging electronic device can set the issuance time of a first task execution instruction or a second task execution instruction.

[0015] In one embodiment, the network manager can be configured by the user to control permissions, that is, when the bridging electronic device issues the first task execution instruction or the second task execution instruction, the network manager verifies the user information of the bridging electronic device, and the first task execution instruction or the second task execution instruction can only be executed after the verification is passed; otherwise, the first task execution instruction or the second task execution instruction will not be executed if the verification is not passed.

[0016] The present invention further provides a data isolation and backup system, which includes at least one source electronic device, one bridging electronic device, one target backup electronic device and one network manager, wherein the source electronic device, the bridging electronic device, the target backup electronic device and the network manager perform the above-described data isolation and backup method.

[0017] Based on the above invention, the target backup electronic device forms an electronic device that is isolated from public networks or external networks, meaning that external cybersecurity threats cannot directly enter the target backup electronic device through public networks or external networks.

Implementation Method

[0018] The following describes the implementation of the present invention through specific embodiments. Those skilled in the art can easily understand other advantages and effects of the present invention from the content disclosed in this specification.

[0019] Figure 1 is a schematic diagram of the architecture of a data isolation and backup system according to an embodiment of the present invention. The data isolation and backup system includes a source electronic device 11, a network manager 12, a bridging electronic device 13, and a target backup electronic device 14.

[0020] In one embodiment, the source electronic device 11, the bridging electronic device 13, and the target backup electronic device 14 may be a computer, a mobile communication device, a network-attached storage server, or a directly connected storage server; the network manager 12 may be a router, a switch, or a gateway; the source electronic device 11, the bridging electronic device 13, and the target backup electronic device 14 may be connected to the network manager 12 via wired or wireless network communication.

[0021] The source electronic device 11, network manager 12, bridging electronic device 13 and target backup electronic device 14 can be used to execute the data isolation backup method shown in FIG2.

[0022] First, in step 201, the network manager 12 is connected to the bridging electronics 13.

[0023] In step 202, the bridging electronic device 13 sends a first task execution instruction to the network manager 12.

[0024] In step 203, the network manager 12 is connected to the source electronic device 11.

[0025] In step 204, the network manager 12 sends the first task execution instruction to the source electronic device 11.

[0026] In one embodiment, the first task execution instruction may include a backup instruction, a synchronization instruction, a source electronic device communication connection instruction, or a first data range.

[0027] In step 205, the source electronic device 11 copies and transmits the first data to the bridging electronic device 13 according to the first task execution instruction.

[0028] In one embodiment, the selection of the first data can be determined by the source electronic device 11 based on the importance of the data. The determination method includes: the user of the source electronic device 11 sets a corresponding data importance weight according to the type of each data, and sets a data importance threshold; the source electronic device 11 calculates the data importance score according to the number of times each data is read and the data importance weight; when the source electronic device 11 determines that the importance score of a data is greater than the data importance threshold, the data is selected as the first data.

[0029] The selection of the first data based on the importance of the file can also be performed by an artificial intelligence system, which is installed in the source electronic device 11. The method may include: the artificial intelligence system setting corresponding data importance weights according to the type of each data, and setting a data importance threshold; the artificial intelligence system calculating the data importance score according to the number of times each data is read and the data importance weight; when the artificial intelligence system determines that the importance score of a data is greater than the data importance threshold, the data is selected as the first data; and the judgment model is continuously optimized based on historical calculation results, and the data importance weights and data importance thresholds are dynamically adjusted.

[0030] In step 206, the bridging electronic device 13 stores the first data.

[0031] In step 207, the bridging electronic device 13 sends a second task execution instruction to the network manager 12.

[0032] In one embodiment, the second task execution instruction may include a backup instruction, a synchronization instruction, a target backup electronic device communication connection instruction, a source electronic device interruption communication connection instruction, or a second data range.

[0033] In one embodiment, the network manager 12 can be configured by the user to control permissions. That is, when the bridging electronic device 13 issues the first task execution instruction or the second task execution instruction, the network manager 12 verifies the user information of the bridging electronic device 13. Only after the verification is passed can the first task execution instruction or the second task execution instruction be executed; otherwise, if the verification is not passed, the first task execution instruction or the second task execution instruction will not be executed.

[0034] In step 208, the network manager 12 interrupts the communication connection with the source electronic device 11.

[0035] In step 209, the network manager 12 communicates with the target backup electronic device 14.

[0036] In step 210, the bridging electronic device 13 copies and transmits the second data to the target backup electronic device 14 according to the second task execution instruction.

[0037] In step 211, the target backup electronic device 14 stores the second data.

[0038] In step 212, the network manager 12 disconnects the communication connection with the target backup electronic device 14.

[0039] In one embodiment, the communication connection between the network manager 12 and the source electronic device 11, and the communication connection interruption between the bridging electronic device 13 and the target backup electronic device 14 can be accomplished by the network manager 12 turning on and off the power supply of the connection port between the network manager 12 and the source electronic device 11, the bridging electronic device 13 and the target backup electronic device 14.

[0040] In one embodiment, after the source electronic device 11 detects the security of a public network or an external network, the source electronic device 11 can be communicatively connected to the public network or the external network.

[0041] In one embodiment, the bridging electronic device 13 may be communicatively connected to a private network or an intranet.

[0042] In one embodiment, the bridging electronic device 13 has a task scheduling function, through which the user of the bridging electronic device 13 can set the issuance time of the first task execution instruction or the second task execution instruction.

[0043] In one embodiment, the target backup electronic device 14 may be communicatively connected to a private network or an intranet.

[0044] In one embodiment, when the communication connection between the network manager 12 and the source electronic device 11 or the target backup electronic device 14 is interrupted, the source electronic device 11 or the target backup electronic device 14 may hibernate or shut down. When the communication connection with the network manager 12 is restored, the hibernation or power-on is activated, thereby saving energy consumption.

[0045] In one embodiment, the method for performing a backup task may be a full backup, an incremental backup, a differential backup, or a cloud backup.

[0046] Among them, full backup is a method of completely backing up all selected data. It usually involves copying all files in the entire folder to the backup device. This method has complete data recovery capabilities, but requires a large amount of storage space and a long backup time.

[0047] Among them, incremental backup only backs up the data that has changed since the last backup. Although the backup efficiency is higher than that of full backup, the data recovery process is more complicated. It is necessary to restore the last full backup data and then restore the incremental backup data in sequence.

[0048] Among them, differential backup is a backup of data that differs from the previous full backup. Compared with incremental backup, the recovery process of differential backup is simpler, but the required storage space and backup time are larger than those of incremental backup.

[0049] Among them, cloud backup transmits data to a remote server to achieve cross-location data protection. However, the data transmission and recovery speed depend on the stability and bandwidth of the network connection. Moreover, storing sensitive data on an external server raises concerns about data security and privacy.

[0050] Figure 3 is a schematic diagram of an electronic device 300 according to an embodiment of the present invention. In this embodiment, the electronic device 300 may be a computer, a mobile communication device, a network-attached storage server, or a storage server directly connected to it, but is not limited thereto.

[0051] In this embodiment, the electronic device 300 includes a processor 302, a storage device 304, a memory 312, and a connection port 314, wherein the processor 302 is communicatively connected to the storage device 304, the memory 312, and the connection port 314.

[0052] In this embodiment, the storage device 304 may be a mechanical hard disk, a solid-state hard disk or a virtual hard disk, but is not limited thereto.

[0053] In this embodiment, memory 312 may include modules such as rule module 306, backup module 308, read / write module 310 or network detection module 316.

[0054] In this embodiment, the processor 302 of the electronic device 300 can load and execute the rule module 306, the backup module 308, the read / write module 310, and the network detection module 316 to perform the data isolation backup method shown in FIG2. The rule module 306 is used to manage first task execution instructions, second task execution instructions, or scheduled tasks; the backup module 308 is used to manage and execute the backup tasks of the electronic device 300; the read / write module 310 is used to write data to each storage device 304 and read data from the storage device 304; and the network detection module 316 is used to detect the security of the network when the electronic device 300 is connected to an external network or a public network.

[0055] Figure 4 is a schematic diagram of a network manager 400 according to one embodiment of the present invention.

[0056] In this embodiment, the network manager 400 includes a processor 402, a connection port 404, a management interface 406, and a memory 410.

[0057] In this embodiment, the memory 410 includes at least a connection management module 412.

[0058] In this embodiment, the processor 402 can load and execute the connection management module 412 to perform the data isolation and backup method shown in FIG2. The connection management module 412 is used by the network manager 400 to perform the task of turning the power on or off of the corresponding connection port when it receives a first task execution instruction or a second task execution instruction.

[0059] In this embodiment, the management interface 406 allows the user of the network manager 400 to set permissions and store the set permissions in the connection management module 412, and allows the user to view the records of electronic devices connected to the network manager 400.

[0060] In one embodiment, each of the above modules may be software or hardware; if it is hardware, the module may be a processing unit, processor, computer or server with data processing and computing capabilities; if it is software, it may include instructions executable by the processing unit, processor, computer or server, and may be installed on the hardware device.

[0061] To illustrate the present invention more clearly, Figures 5a to 5f provide a simplified flowchart of a data isolation backup system according to an embodiment.

[0062] As shown in Figure 5a, the network manager 12 is only connected to the bridging electronics 13. This is the normal state before the system performs its first task.

[0063] As shown in Figure 5b, the bridging electronic device 13 sends a first task execution instruction to the network manager 12. The network manager 12 is communicatively connected to the source electronic device 11 and sends the first task execution instruction to the source electronic device 11. This state enables the bridging electronic device 13 to communicate with the source electronic device 11.

[0064] As shown in FIG5c, the source electronic device 11 copies and transmits the first data to the bridging electronic device 13 according to the first task execution instruction, and the bridging electronic device 13 stores the first data. This state enables the bridging electronic device 13 to obtain the first data stored in the source electronic device 11.

[0065] As shown in Figure 5d, after the bridging electronic device 13 acquires the data stored in the source electronic device 11, the bridging electronic device 13 sends a second task execution instruction to the network manager 12. The network manager 12 then disconnects its communication connection with the source electronic device 11 and establishes a communication connection with the target backup electronic device 14. This state enables the bridging electronic device 13 to communicate with the target backup electronic device 14 and disconnects its communication connection with the source electronic device 11.

[0066] As shown in Figure 5e, the bridging electronic device 13 copies and transmits the second data to the target backup electronic device 14 according to the second task execution instruction, and the target backup electronic device 14 stores the second data. This state enables the target backup electronic device 14 to obtain the second data stored in the bridging electronic device 13 even without communication connection with external networks or public networks, and prevents cybersecurity threats from entering the target backup electronic device 14 to steal the data stored on this device.

[0067] As shown in Figure 5f, the network manager 12 interrupts the communication connection with the target backup electronic device 14.

[0068] The above description is merely illustrative of the implementation method of the present invention and is not intended to limit the present invention. Therefore, the scope of protection of the present invention should be as indicated in the following patent application scope. [Simplified Explanation of the Diagram]

[0069] [Figure 1] Schematic diagram of the architecture of a data isolation backup system according to an embodiment of the present invention [Figure 2] Flowchart of a data isolation backup method according to an embodiment of the present invention [Figure 3] Schematic diagram of an electronic device according to an embodiment of the present invention [Figure 4] Schematic diagram of a network manager according to an embodiment of the present invention [Figures 5a]~[Figures 5f] Flowchart of a data isolation backup system according to an embodiment of the present invention

Claims

1. A method for data isolation and backup, comprising at least one source electronic device, at least one bridging electronic device, at least one target backup electronic device, and at least one network manager, wherein, The method includes the following steps: The network manager is communicatively connected to the bridging electronic device; The bridging electronic device sends a first task execution instruction to the network manager; The network manager is communicatively connected to the source electronic device and sends the first task execution instruction to the source electronic device; The source electronic device copies and transmits first data to the bridging electronic device according to the first task execution instruction, and the bridging electronic device stores the first data; The bridging electronic device sends a second task execution instruction to the network manager; The network manager disconnects its communication connection with the source electronic device and becomes communicatively connected to the target backup electronic device; The bridging electronic device copies and transmits second data to the target backup electronic device according to the second task execution instruction, and the target backup electronic device stores the second data; The network manager disconnects its communication connection with the target backup electronic device.

2. As in request item 1, the data isolation and backup method, wherein, The source electronic device is an electronic device, the first data originates from the source electronic device; and, after the source electronic device detects the security of a public network or an external network, it can communicate and connect to the public network or the external network.

3. As in request item 1, the data isolation and backup method, wherein, The bridging electronic device is an electronic device that can communicate with a private network or intranet; and the bridging electronic device has a task scheduling function, through which the user of the bridging electronic device can set the time for issuing a first task execution command or a second task execution command.

4. As in request item 1, the data isolation and backup method, wherein, The target backup electronic device is an electronic device for storing second data and can be communicatively connected to a private network or an intranet; and, through this method, the target backup electronic device forms an electronic device with the property of being isolated from public networks or external networks.

5. As in request item 1, the data isolation and backup method, wherein, The network manager can be a router, switch, or gateway, and can be configured by the user to control permissions. That is, when the bridging electronic device issues the first task execution command or the second task execution command, the network manager verifies the user information of the bridging electronic device. Only after the verification is successful can the first task execution command or the second task execution command be executed; otherwise, if the verification fails, the first task execution command or the second task execution command will not be executed.

6. As in request item 1, the data isolation and backup method, wherein, The first task execution instruction may include a backup instruction, a synchronization instruction, a source electronic device communication connection instruction, or a first data range.

7. As in request item 1, the data isolation and backup method, wherein, The first data refers to the data copied and transmitted to the bridging electronic device by the source electronic device according to the first data range of the first task execution instruction.

8. As in request item 1, the data isolation and backup method, wherein, The second task execution instruction may include a backup instruction, a synchronization instruction, a target backup electronic device communication connection instruction, a source electronic device interruption communication connection instruction, or a second data range.

9. The data isolation and backup method as requested in item 1, wherein, The second data refers to the data copied and transmitted to the target backup electronic device by the bridging electronic device according to the second data range of the second task execution instruction, and the second data may be different from the first data.

10. A data isolation and backup system comprising at least one source electronic device, one bridging electronic device, one target backup electronic device, and one network manager, wherein the source electronic device, the bridging electronic device, the target backup electronic device, and the network manager execute the isolation and backup method of requests 1 to 9.